CVE-2020-17353
05.08.2020, 14:15
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.Enginsight
Vendor | Product | Version |
---|---|---|
lilypond | lilypond | 𝑥 ≤ 2.20.0 |
lilypond | lilypond | 2.21.0 ≤ 𝑥 ≤ 2.21.4 |
debian | debian_linux | 10.0 |
opensuse | backports_sle | 15.0:sp2 |
opensuse | leap | 15.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References